XInet K-AShare XKAS Program World Writable Icon Directory Vulnerability
BID:3969
Info
XInet K-AShare XKAS Program World Writable Icon Directory Vulnerability
| Bugtraq ID: | 3969 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 28 2002 12:00AM |
| Updated: | Jan 28 2002 12:00AM |
| Credit: | This vulnerability was announced by <[email protected]> via Bugtraq on January 28, 2002. |
| Vulnerable: |
Xinet K-AShare for IRIX 11.1 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 |
| Not Vulnerable: |
SGI IRIX 6.5.16 |
Discussion
XInet K-AShare XKAS Program World Writable Icon Directory Vulnerability
K-AShare is a file sharing system designed to allow Apple Macintosh and Unix systems to share resources. It is maintained and distributed by Xinet.
A default installation of K-AShare installs an icon directory used by the system with insecure permissions. One of the files in this directory, 'VOLICON', is copied to a directory being shared by an administrator through the 'xkas' GUI utility. As a result of the icon directory permissions, a local user could remove the VOLICON file and create a symbolic link to an unreadable file such as '/etc/shadow'. When the superuser executes the xkas program and shares a directory, the '/etc/shadow' file would be copied to the shared directory as file '.HSicon' with world-readable permissions.
K-AShare is a file sharing system designed to allow Apple Macintosh and Unix systems to share resources. It is maintained and distributed by Xinet.
A default installation of K-AShare installs an icon directory used by the system with insecure permissions. One of the files in this directory, 'VOLICON', is copied to a directory being shared by an administrator through the 'xkas' GUI utility. As a result of the icon directory permissions, a local user could remove the VOLICON file and create a symbolic link to an unreadable file such as '/etc/shadow'. When the superuser executes the xkas program and shares a directory, the '/etc/shadow' file would be copied to the shared directory as file '.HSicon' with world-readable permissions.
References
XInet K-AShare XKAS Program World Writable Icon Directory Vulnerability
References:
References: